Junglewise Threat Intelligence

CVE-2026-13356: Mozilla Firefox for iOS address bar origin spoofing

CVE-2026-13356 · Severity: info · CVSS 0 · Published 2026-07-07

Technologies: Mozilla Firefox for iOS. Vendors: Mozilla.

Executive brief

A security flaw in Firefox for iOS allows a malicious website to trick users by displaying a fake web address in the browser's address bar. While the address bar shows a legitimate site, the browser continues to display content controlled by the attacker. This could be used in phishing attacks to steal login credentials or sensitive information by making a fraudulent site appear trustworthy.

Technical details

An address bar spoofing vulnerability exists in Firefox for iOS due to improper handling of synchronous JavaScript dialogs during navigation. By enqueuing a dialog (such as an alert or prompt) at the moment a user navigates to a new site, an attacker can interrupt the transition process. This results in a state where the browser updates the URL bar to the new destination origin while the rendering engine remains on the attacker's page. This allows for sophisticated phishing attacks where the user believes they are on a trusted domain. The issue is resolved in Firefox for iOS version 152.3.

Affected products

  • Mozilla Firefox for iOS < 152.3

Timeline

  • 2026-07-05: advisory: Mozilla Foundation Security Advisory 2026-65 released
  • 2026-07-07: disclosed: CVE-2026-13356 published to NVD

References

Related threats